Total vulnerabilities in the database
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module name.
Software | From | Fixed in |
---|---|---|
freepbx / freepbx | 15.0.1 | 15.0.1.x |
sangoma / freepbx | - | 13.0.122.43 |
sangoma / freepbx | 14.0.0 | 14.0.18.34 |
sangoma / freepbx | 15.0.1-beta4 | 15.0.1-beta4.x |
sangoma / freepbx | 15.0.0 | 15.0.1.x |